StackRadar

CVE-2023-30608

High

Advisory

Published 18 Apr 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
60th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
2 of 2
affected packages

sqlparse contains a regular expression that is vulnerable to Regular Expression Denial of Service

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
sqlparsedeb0.2.4-30.2.4-3ubuntu0.11
sqlparsepypi0.1.16, 0.2.2, 0.2.4, 0.3.0+4 more0.4.452
OSV records
UBUNTU-CVE-2023-30608GHSA-rrm6-wvj7-cwh2
Also known as
PYSEC-2023-87, USN-6064-1

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.4.4

Open the chart page →

5,456
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.4.4

Open the chart page →

22,084
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
sqlparse@0.3.1
0.4.4

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
0.2.4-3ubuntu0.1
0.4.4

Open the chart page →

30,687
pgadminstakaterVerified publisher0.1.141 of 1See more

pgadmin stakater 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.4.4

Open the chart page →

2,060
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-30608.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.4.4

Open the chart page →

3,392

Container images carrying it

52 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
sqlparse@0.4.2
0.4.4
3
dpage/pgadmin4:6.12781369df9994
sqlparse@0.4.2
0.4.4
3
amancevice/superset:0.35.212a0a9e66550
sqlparse@0.3.0
0.4.4
2
larribas/mlflow:1.9.105ccb0b46bfb
sqlparse@0.3.1
0.4.4
2
weblate/weblate:4.2.2-169c160d37a3c
sqlparse@0.3.1
0.4.4
2
alexeyr7/sf-test-app:latestdf0b41fdbd53
sqlparse@0.4.2
0.4.4
1
amancevice/superset:0.28.1c8c04bfe3d66
sqlparse@0.2.4
0.4.4
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
sqlparse@0.3.0
0.4.4
1
buntha/mlflow:2.1.1154542cc3083
sqlparse@0.4.3
0.4.4
1
chorss/docker-pgadmin4:4.115c549cacb8ab
sqlparse@0.2.4
0.4.4
1
dpage/pgadmin4:4.5a5a656e1d5fd
sqlparse@0.2.4
0.4.4
1
dpage/pgadmin4:4.22b1f00b8163cf
sqlparse@0.2.4
0.4.4
1
evk02/mlflow:2.2.1ef6ff257ef35
sqlparse@0.4.3
0.4.4
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
sqlparse@0.2.4
0.4.4
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
sqlparse@0.4.1
0.4.4
1
galaxy/cloudman-server:lateste5c265fe9fcd
sqlparse@0.4.2
0.4.4
1
galaxy/galaxy-init:v18.010267bad550e6
sqlparse@0.1.16
0.4.4
1
gethue/hue:4.11.011b649636e68
sqlparse@0.4.2
0.4.4
1
gethue/hue:4.10.05702b2c37ff9
sqlparse@0.4.1
0.4.4
1
gluufederation/opendj:4.3.0_011a1128b28b95
sqlparse@0.4.2
0.4.4
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
sqlparse@0.3.1
0.4.4
1
ha33ona/python:test6affdfc644d0
sqlparse@0.4.2
0.4.4
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
sqlparse@0.4.3
0.4.4
1
hhyo/archery:v1.9.11aa41843419e
sqlparse@0.4.3
0.4.4
1
improwised/erpnext-worker:v13.4.197280b55cbd4
sqlparse@0.4.1
0.4.4
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
sqlparse@0.4.2
0.4.4
1
kobotoolbox/kobocat:2.022.24ab15679454415
sqlparse@0.4.2
0.4.4
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
sqlparse@0.4.2
0.4.4
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
sqlparse@0.4.2
0.4.4
1
linuxserver/babybuddy:1.10.2f7d7c7704249
sqlparse@0.4.2
0.4.4
1
linuxserver/healthchecks:version-v1.20.050792a72fc71
sqlparse@0.4.1
0.4.4
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
sqlparse@0.4.3
0.4.4
1
milesmcc/shynet:v0.12.0e821e31140f7
sqlparse@0.4.2
0.4.4
1
netboxcommunity/netbox:v3.2.83d652dca5351
sqlparse@0.4.2
0.4.4
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
sqlparse@0.4.1
0.4.4
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
sqlparse@0.4.1
0.4.4
1
openzaak/open-notificaties:1.3.02e65313b9b10
sqlparse@0.4.2
0.4.4
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
sqlparse@0.4.2
0.4.4
1
redash/redash:10.0.0.b503639392753c0376
sqlparse@0.3.0
0.4.4
1
seafileltd/seafile-mc:9.0.106693911bcc40
sqlparse@0.4.3
0.4.4
1
seafileltd/seafile-mc:10.0.170628f29c663
sqlparse@0.4.3
0.4.4
1
seafileltd/seafile-mc:9.0.97ac833196f60
sqlparse@0.4.2
0.4.4
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
sqlparse@0.4.1
0.4.4
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
sqlparse@0.2.4-3
sqlparse@0.2.4
0.2.4-3ubuntu0.1
0.4.4
1
statcan/ckan:2.93921305425b8
sqlparse@0.2.2
0.4.4
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
sqlparse@0.4.3
0.4.4
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
sqlparse@0.4.3
0.4.4
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
sqlparse@0.4.3
0.4.4
1
taigaio/taiga-back:6.4.29f97323cc150
sqlparse@0.4.1
0.4.4
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
sqlparse@0.4.2
0.4.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.